A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc.
A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A spe
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Sys
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Sys
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Sys
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Sys
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-
An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One S
An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A special
An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Se
An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16
A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In
An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Se
A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security K
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Inj
An OS command injection vulnerability exists in the console_main_loop :sys functionality of Abode Systems, Inc. iota All
An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc.
An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, In
An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One
An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, In
Stack-based buffer overflow in WTViewerE series WTViewerE 761941 from 1.31 to 1.61 and WTViewerEfree from 1.01 to 1.52 a
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allow
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions < V22.2a (80)). The mobile
On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. Y
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that
Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=
Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.j
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the messag
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the time parameter at /go
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter at
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the firewallEn parameter
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /g
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /go
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax fu
Frequently Asked Questions
What does CRITICAL severity mean for CVEs?
CVSS 9.0–10.0 — vulnerabilities that allow remote code execution, full system compromise, or trivial exploitation with no authentication required
How many critical severity CVEs exist?
There are 35,149 CVE records rated CRITICAL in our database. Of these, 312 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize critical severity vulnerabilities?
CRITICAL severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect CRITICAL Vulnerabilities
CyberStrike scans your infrastructure and detects critical severity vulnerabilities in real time.
Get Started